Ahmad, Liyanage, Shahabuddin, Ylianttila, and Gurtov
80
deplete the resources of the network operator infrastructure that serves the users and
devices. Though the original target is the operator network, the subscribers are indirectly affected. Attacks against users/devices are designed to deplete the resources of
the users and devices. In this case, the subscribers and devices are directly targeted, but
this impacts the network operator indirectly. Compromised user devices can also be
used to cause the attacks against the network infrastructure.
DoS attacks on 5G network infrastructure would likely target the resources that are
related to connectivity and bandwidth at promised levels of service. Hence, the focus
can be against the following areas:
1) the signaling plane needed for authentication, connectivity and bandwidth assignment, and mobility of 5G users;
2) user plane needed to support two‐way communication of devices;
3) management plane that supports the configuration of network elements that support signaling and user planes;
4) support systems that performs user/devices billing;
5) radio resources providing access to user devices; and
6) physical and logical resources supporting network clouds.
DoS attacks against the user devices will target the physical resources of the user devices
such as memory, battery, processing units, radios, and sensors, etc. These attacks can
also target the logical resources such as operating systems, applications, configuration
data, and user data, etc.
4.2.3.3 Security Challenges in the Control Layer or Core Network
The massive penetration of IP protocols in the control and user planes in all network
functions make the 5G core network highly vulnerable. Hence the network must be
capable of ensuring availability with improved resilience against signaling‐based threats.
Specific security features must be incorporated for latency sensitive applications and
use cases. The network must also incorporate the security requirements defined by the
3GPP. Furthermore, 5G networks should ensure communication in emergency situations such as when part of the network is either inaccessible or destroyed.
Overloading the signaling plane with huge number of infected IoT or M2M devices,
either as an attempt of DoS attack or to gain access to the network, will be another
pressing challenge in 5G networks [7]. IoT devices, in billions [46], will be resource
constrained, thus making two kinds of requests. First, due to limited capabilities, these
devices will require the resources in the clouds to perform processing, storing or sharing
of information. Second, also due to their limited capabilities, these will be an easy target
to masquerade or operate in a compromised environment for attacks on the network in
the form of DoS attacks. Hence, the increasing number of connected devices will be a
huge challenge for the signaling plane or core network of 5G networks. An example of
this is the authentication and authorization requests to the HSS, which can potentially
make the HSS inaccessible to legitimate users, in other words, compromise the centralized entity through a DoS attack or saturation attack [48].
The increasing range of communication services and devices leads to high traffic
volumes for signaling purposes, such as authentication and bearer activation. Such
traffic bursts bring about a signaling storm and may crash the core network [1].
Similarly, the signaling procedures occur at the NAS layer of 3GPP protocols that
Précédent

- 122/483

Suivant